Issue #22005 has been updated by vo.x (Vit Ondruch). One more question. What is the process with H1 disclosure? Because to me it seems that the H1 report is still private despite being referenced in the GHSA ---------------------------------------- Misc #22005: Missing information about CVE on cve.org https://bugs.ruby-lang.org/issues/22005#change-117054 * Author: vo.x (Vit Ondruch) * Status: Closed * Assignee: hsbt (Hiroshi SHIBATA) ---------------------------------------- The CVE-2026-27820 was fixed and disclosed more than one month ago: https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-2... However, there is still no public information on https://www.cve.org/CVERecord?id=CVE-2026-27820 . Could this be fixed please? BTW the same situation was for CVE-2025-61594, where the information was not there for months. This points to a gap in a security release process. Could the process be improved so the information is disclosed in timely manner? -- https://bugs.ruby-lang.org/